# NIST AI RMF and ISO 42001 for Law Firms: A Practical Path

> How to apply the NIST AI Risk Management Framework and ISO 42001 inside a law firm, mapped to your bar duties, without a full enterprise compliance team.

[Home](https://rankshieldlegal.com/) / [Blog](https://rankshieldlegal.com/blog/) / Legal AI Governance frameworks
# Applying the NIST AI Risk Management Framework and ISO 42001 in a Law Firm
Every AI governance essay tells law firms to align with the NIST AI Risk Management Framework or ISO 42001, and almost none explains what that means for a firm that is not a Fortune 500 company. The frameworks were written for organizations building and deploying AI at scale, not for a practice that mainly uses tools others built. This guide translates both into a practical path a firm can actually walk, mapped to the bar duties you already carry.

By [Jamie Kloncz](https://rankshieldlegal.com/about/), Founder, RankShield ** 16 min read ** Published August 22, 2026

Applying the NIST AI RMF in a law firm does not require an enterprise compliance team; it requires mapping the framework's functions onto duties you already have. The NIST AI Risk Management Framework, published in January 2023, organizes AI risk into four functions, Govern, Map, Measure, and Manage, and ISO/IEC 42001, published in December 2023 as the first international AI management system standard, provides an auditable structure for governing AI use [[1]](#ref-1) [[2]](#ref-2). For a firm, both are less a new burden than a scaffold for the confidentiality, competence, and supervision duties that ABA Formal Opinion 512 already imposes [[3]](#ref-3).
The reason these frameworks feel out of reach is that their language assumes an organization developing AI systems. A law firm is almost always a deployer of tools, not a builder, so most of the heaviest requirements, model development controls and the like, simply do not apply. What remains is a manageable set of governance practices, and mapping them to Model Rules you already follow turns an intimidating standard into a checklist you can staff.
This guide is written from the perspective of a verification vendor, not a law firm, and it is informational rather than legal advice. It explains what the two frameworks are, maps their functions to your ethics obligations, lays out a phased adoption path, describes what to document at each phase, and identifies where a small firm can stop and still be defensible.

## NIST AI RMF and ISO 42001, briefly
The NIST AI RMF is a voluntary US framework organizing AI risk into four functions: Govern (set policy and accountability), Map (identify context and risks), Measure (assess and track them), and Manage (act on them). ISO/IEC 42001 is a certifiable international standard for an AI management system, the AI equivalent of ISO 27001 for security. One is a flexible framework; the other is an auditable management system [[1]](#ref-1) [[2]](#ref-2).
The two are complementary rather than competing. The NIST AI RMF, released in January 2023, is voluntary and flexible: it does not certify anything, but it gives a common structure for thinking about AI risk through its Govern, Map, Measure, and Manage functions. Govern sits at the center, establishing policy, roles, and accountability that the other three functions operate within.
ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system, and unlike the NIST framework it is certifiable, meaning an accredited auditor can assess conformance. It defines a managed, auditable process for how an organization develops, provides, and uses AI, in the same family as ISO/IEC 27001 for information security.
For a firm, the practical difference is intent. Use the NIST AI RMF as the thinking tool that structures your program, and treat ISO/IEC 42001 as the target if you ever want an external certification to show clients or insurers. Most firms start with the former and grow toward the latter only if the market demands it.

## Mapping the frameworks to your ethics obligations
The frameworks map cleanly onto duties you already hold. Govern aligns with the supervision duty under Model Rules 5.1 and 5.3; Map aligns with competence under Rule 1.1, understanding the tools you use; Measure and Manage align with the confidentiality duty under Rule 1.6, tracking and controlling how client data is exposed. Framed this way, adoption is formalizing existing obligations, not adding new ones [[3]](#ref-3).
The fastest way to make these frameworks concrete for a firm is to stop treating them as foreign and map each function to the Model Rule it already serves. The table below does that.
Framework function Maps to bar duty What it means for a firm
Govern (NIST) / Leadership (ISO) Supervision, Rules 5.1 and 5.3 A written AI policy, named accountability, staff oversight [3]
Map (NIST) Competence, Rule 1.1 Know which tools are used and what they do with data
Measure (NIST) Confidentiality, Rule 1.6 Track where client data goes and assess the exposure
Manage (NIST) / Operation (ISO) Confidentiality and competence Apply controls, log use, respond to incidents
Continual improvement (ISO) Ongoing competence Review and update as tools and rules change

Source: NIST AI RMF 1.0 (2023); ISO/IEC 42001:2023; ABA Formal Opinion 512 Download SVG

## A phased adoption path for a firm
Adopt in three phases. Phase one is Govern: write an AI policy, name an owner, and inventory the tools in use. Phase two is Map and Measure: classify each tool's data exposure and confidentiality risk. Phase three is Manage: apply controls, log use, and add incident response. A small firm can complete phase one in weeks and mature through the others rather than attempting everything at once.
Trying to stand up a full AI management system in one project is how firms stall. Phase the work so each stage delivers something defensible on its own.
Phase one, Govern, is the foundation and the fastest win: a written AI policy, a named person accountable for it, and an inventory of the AI tools actually in use. Our guide on [building a defensible AI policy](https://rankshieldlegal.com/blog/law-firm-ai-policy) covers the policy itself. Phase two, Map and Measure, classifies each tool by what data it touches and how much confidentiality risk it carries, which is where the audit work from a firm-wide AI inventory feeds in. Phase three, Manage, applies the controls: access rules, usage logging, vendor requirements, and an incident-response plan.
Because these frameworks are voluntary for a firm, you set the depth. The value is not a certificate; it is that each phase makes an existing duty operational, and the sequence lets a firm show steady, documented progress rather than an all-or-nothing effort.

## What to document at each phase
Document enough to show the program is real: in Govern, the written policy and the accountable owner; in Map and Measure, the tool inventory and a risk classification per tool; in Manage, the controls applied, the usage log, and the incident-response plan. The documentation is both the governance and the evidence, because a framework you followed but cannot show is indistinguishable from one you skipped.
The documentation is not bureaucracy for its own sake; it is what converts a governance intention into something a client, insurer, or regulator can credit. Keep it proportionate to the firm, but keep it.
In the Govern phase, retain the written AI policy and a record of who owns it. In Map and Measure, keep the tool inventory and the risk classification you assigned to each tool, including which handle privileged data. In Manage, document the controls you applied, the log of AI use, and the incident-response plan, along with evidence that the plan has been tested. Where the program touches how AI acts on client matters, tie the documentation to the specific tools, which is where the [agentic AI governance gap](https://rankshieldlegal.com/blog/agentic-ai-governance-gap-law-firms) becomes concrete.
A living set of these documents is what an ISO/IEC 42001 auditor would look for and what an insurer increasingly asks about, so building them during adoption serves both the duty and any later external review.

## Where a small firm can stop and still be defensible
A small firm can stop after Govern and a light Map and Measure and still be defensible: a written AI policy, a named owner, a current tool inventory, a basic risk classification, and a simple usage log. Full ISO/IEC 42001 certification is optional and market-driven, not a duty. The defensible minimum is showing you know your tools, control your client data, and supervise their use.
Not every firm needs the full framework, and pretending otherwise is how good governance gets abandoned as too heavy. The honest floor is lower than the frameworks imply, because most of their weight targets AI builders.
For a small firm, a defensible program is a written policy, a named owner, a current inventory of the AI tools in use, a basic classification of which tools touch privileged data, and a simple record of use and any incidents. That set demonstrates competence, confidentiality control, and supervision, which are the duties that actually bind you. Scale up toward ISO/IEC 42001 certification only if clients, insurers, or your own risk appetite call for it.
The goal is proportion. A frame that is right-sized and actually maintained protects the firm and its clients far better than an enterprise program that looks impressive on paper and is never kept current.

## Deployer, not developer: why most of the framework does not apply to you
Both frameworks were written with AI builders in view. A law firm almost always deploys tools others built, which makes large parts of each framework inapplicable rather than deferred. Knowing which parts you can set aside is what separates a governance program a firm will maintain from one it abandons as unmanageable [[1]](#ref-1) [[2]](#ref-2).
The most common failure in law firm AI governance is not neglect. It is a firm reading a framework designed for organizations that train and ship models, concluding the program is enormous, and doing nothing.
Much of the NIST AI RMF's substance addresses questions a deployer cannot answer: training data provenance, model architecture decisions, bias testing of the underlying system, and validation of model performance across populations. A firm licensing a commercial drafting tool has no access to any of that and no ability to change it.
What remains for a deployer is genuinely smaller and entirely actionable. Which tools are in use and who authorized them. What categories of client data may enter each one. Who is accountable when something goes wrong. What the firm does when output is wrong. Whether people using the tools understand their limits. That is a real program, and it maps to duties the firm already carries under ABA Formal Opinion 512 rather than to obligations the frameworks invent [[3]](#ref-3).
The deployer framing also redirects one question outward. Where a firm cannot assess model-level risk itself, the framework's demand becomes a procurement demand: require the vendor to show its own governance, its audit posture, and its AI management program. The firm is not excused from the risk; it discharges the obligation by contracting and verifying rather than by testing a model it cannot see.
Read that way, ISO/IEC 42001 becomes most useful to a firm as a vendor-evaluation vocabulary rather than as a certification target. A vendor holding it, or documenting a program against it, is telling you something checkable about how it manages AI risk [[2]](#ref-2).

## What makes a governance program survive its first year
A program fails between the policy and the practice. The three things that keep one alive are a named owner with actual authority, a review cadence tied to events rather than to good intentions, and an inventory that updates when tools change. Without those, a firm ends up with a current document describing a program nobody runs.
Most abandoned governance programs were not badly designed. They were designed once, adopted, and then not touched, while the tools they described kept changing underneath them.
A named owner is the first requirement, and the name has to belong to a person rather than a committee. The owner needs enough authority to say no to a tool, which is the test of whether the role is real. If the answer to "who decides whether we adopt this" is nobody in particular, the policy is descriptive rather than governing.
A review cadence works better when tied to events than to the calendar. An annual review will slip. A rule that any new AI tool requires an inventory entry and a data classification before use, and that any incident triggers a review of the relevant control, fires when something has actually changed and is therefore worth doing.
The inventory is where programs quietly die. A tool list assembled once and never updated becomes actively misleading, because it reads like knowledge while describing a state of the world that has passed. Tie inventory updates to the events that change it: procurement, a new integration in an existing product, and departure or role change for anyone who administered a tool.
The point is not to build toward certification. It is to be able to answer, on any given day, which tools the firm uses, what client data they touch, who approved them, and what happens when they are wrong. A firm that can answer those four questions has a defensible program, whatever it is called [[3]](#ref-3).
4 answers a defensible program can state, on any day: which tools are in use, what data they touch, who approved them, and what happens when they are wrong

Test yourself
## Test yourself on right-sizing AI governance
Five questions on what these frameworks actually ask of a law firm.

- 1 What are the four functions of the NIST AI Risk Management Framework? Plan, Do, Check, Act Govern, Map, Measure, Manage Identify, Protect, Detect, Respond **Answer:** Govern, Map, Measure, Manage Govern sets policy and accountability, Map identifies context and risks, Measure assesses and tracks them, and Manage acts on them. The framework is voluntary and certifies nothing; it supplies a common structure.
- 2 Why does much of each framework not apply to a law firm? Firms are exempt under ABA rules The frameworks target organizations that build and ship models, and a firm deploys They apply only outside the United States **Answer:** The frameworks target organizations that build and ship models, and a firm deploys Training data provenance, model architecture, and bias testing of the underlying system are questions a deployer cannot answer or change. What remains for a firm is smaller and entirely actionable.
- 3 What does the deployer framing do with model-level risk a firm cannot assess? Excuses the firm from it Converts it into a procurement demand on the vendor Defers it until certification **Answer:** Converts it into a procurement demand on the vendor The firm is not excused. It discharges the obligation by requiring the vendor to show its governance, audit posture, and AI management program, then verifying, rather than by testing a model it cannot see.
- 4 What is the defensible floor for a small firm? Full ISO/IEC 42001 certification Written policy, named owner, tool inventory, risk classification, usage log An annual third-party audit **Answer:** Written policy, named owner, tool inventory, risk classification, usage log That set demonstrates competence, confidentiality control, and supervision, which are the duties that actually bind a firm. Certification is optional and market-driven rather than an ethical requirement.
- 5 What most often kills a governance program in its first year? Cost An inventory that stops being updated while the tools keep changing Regulatory change **Answer:** An inventory that stops being updated while the tools keep changing A tool list assembled once becomes actively misleading, because it reads like knowledge while describing a state of the world that has passed. Tie updates to events, procurement, new integrations, and administrator changes, rather than to the calendar.
Honest self-check. There is no sign-up, and nothing is stored.

Questions answered
## Straight answers to the common questions
The questions readers ask about this topic, answered directly. **No forms, no sales pitch.**

JAMIE KLONCZ · SEO AGENCY NAPLES ************** ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

← PREV NEXT → [REQUEST ACCESS →](https://rankshieldlegal.com/contact/)

- **What is the NIST AI Risk Management Framework, and does it apply to law firms?** The NIST AI Risk Management Framework, published in January 2023, is a voluntary US framework that organizes AI risk into four functions: Govern, which sets policy and accountability; Map, which identifies the context and risks of AI use; Measure, which assesses and tracks those risks; and Manage, which acts on them. It is not law and does not apply to law firms as a mandate. But it is a useful scaffold, because its functions map directly onto duties firms already have under the Model Rules, competence, confidentiality, and supervision. Most of the framework's heaviest requirements target organizations that build AI systems, so a firm that mainly deploys tools others built can adopt a lighter version focused on governance, tool inventory, risk classification, and usage logging.
- **What is ISO 42001 and how is it different from the NIST AI RMF?** ISO/IEC 42001, published in December 2023, is the first international standard for an AI management system, and it is certifiable, meaning an accredited auditor can assess whether an organization conforms to it. It defines a structured, auditable process for how an organization governs its development, provision, and use of AI, in the same family as ISO/IEC 27001 for information security. The NIST AI RMF, by contrast, is a voluntary framework rather than a certifiable standard: it gives you a way to think about and structure AI risk but does not certify anything. For a law firm, the practical difference is that you use the NIST framework as the thinking tool that shapes your program and treat ISO 42001 as an optional external certification to pursue only if clients or insurers make it worthwhile.
- **How do these AI frameworks map to a lawyer's ethics duties?** They line up more cleanly than their corporate language suggests. The Govern function corresponds to the supervision duty under Model Rules 5.1 and 5.3: a written policy, named accountability, and oversight of how staff use AI. The Map function corresponds to competence under Rule 1.1: knowing which tools are in use and what they do with data. The Measure and Manage functions correspond to confidentiality under Rule 1.6: tracking where client data goes and applying controls to limit exposure. ISO 42001's continual-improvement requirement corresponds to the ongoing nature of the competence duty as tools and rules change. Framed this way, adopting the frameworks is mostly formalizing obligations you already carry, which is why it is more approachable than it first appears.
- **How should a law firm start adopting the NIST AI RMF or ISO 42001?** Adopt in phases rather than all at once. Phase one is Govern: write an AI policy, name a person accountable for it, and inventory the AI tools actually in use. Phase two is Map and Measure: classify each tool by what data it touches and how much confidentiality risk it carries. Phase three is Manage: apply access controls, log AI use, set vendor requirements, and add an incident-response plan. A small firm can complete phase one in a few weeks and mature through the later phases over time, documenting progress as it goes. Because these frameworks are voluntary for firms, you control the depth, and the sequence lets you show steady, defensible progress instead of attempting an enterprise-grade program in a single effort.
- **Does a small law firm need full ISO 42001 certification?** No. Full ISO/IEC 42001 certification is optional and driven by market demand, not by any ethics rule. A small firm can be defensible with much less: a written AI policy, a named owner, a current inventory of the AI tools in use, a basic classification of which tools handle privileged data, and a simple record of use and any incidents. That set demonstrates the duties that actually bind the firm, competence, confidentiality, and supervision, and it is maintainable by a small team. Pursue certification only if clients, insurers, or your own risk appetite justify the cost. A right-sized program that is actually kept current protects the firm and its clients better than an enterprise-grade one that looks thorough on paper but is never updated.
- **Does a law firm need ISO/IEC 42001 certification?** No. Certification is market-driven rather than an ethical requirement, and no bar rule obliges a firm to obtain it. ISO/IEC 42001, published in December 2023 as the first international AI management system standard, is genuinely useful to a firm in two other ways. It supplies a vocabulary for evaluating vendors, since a vendor holding the certification or documenting a program against it is telling you something checkable about how it manages AI risk. And it offers a structure to grow into if clients, insurers, or your own risk appetite eventually call for it. Pursue certification when a specific stakeholder is asking for it, not on the assumption that governance means certification. The duties that actually bind a firm are competence, confidentiality, and supervision.
- **Who should own AI governance in a law firm?** A named individual with enough authority to decline a tool, not a committee. The authority test is the real one: if the answer to "who decides whether we adopt this" is nobody in particular, the policy describes a program rather than governing one. The owner does not need to be a technologist, and in many firms the role sits better with someone who understands the practice's confidentiality exposure than with someone who understands the models. Pair the role with an event-driven cadence rather than an annual review, since an annual review slips: require an inventory entry and a data classification before any new tool is used, and trigger a review of the relevant control whenever an incident occurs. The measure of whether the role is working is whether the firm can state, on any given day, which tools it uses, what client data they touch, who approved them, and what happens when they are wrong.

## References

- National Institute of Standards and Technology. AI Risk Management Framework (AI RMF 1.0). January 2023. [https://www.nist.gov/itl/ai-risk-management-framework](https://www.nist.gov/itl/ai-risk-management-framework)
- International Organization for Standardization. ISO/IEC 42001:2023 Artificial Intelligence Management System. December 2023. [https://www.iso.org/standard/81230.html](https://www.iso.org/standard/81230.html)
- American Bar Association. Formal Opinion 512: Generative Artificial Intelligence Tools. July 2024. [https://www.americanbar.org/news/abanews/aba-news-archives/2024/07/aba-issues-first-ethics-guidance-ai-tools/](https://www.americanbar.org/news/abanews/aba-news-archives/2024/07/aba-issues-first-ethics-guidance-ai-tools/)

Written by
## [Jamie Kloncz](https://rankshieldlegal.com/about/)
Founder, RankShield
Jamie Kloncz is the founder of RankShield, the verifiable AI and quantum security platform behind RankShield Legal. An engineer by training, he built RankShield after his own devices and business were attacked, including an AI voice-cloning scam that targeted his family, on one conviction: unverifiable security is the real danger, so every consequential action should leave a receipt anyone can independently check.
[More about Jamie →](https://rankshieldlegal.com/about/)

Try it · Free
## Check a citation against live case-law
Paste a citation from an AI-drafted brief and see whether the case actually exists, resolved against live case-law. Free, no sign-up. Then request early access to certify a full filing.
[Try the citation checker](https://rankshieldlegal.com/ai-legal-citation-checker/)

Keep reading
## Related guides
[Legal AI Building a Defensible Law Firm AI Policy Read guide →](https://rankshieldlegal.com/blog/law-firm-ai-policy/)[Legal AI When Your AI Stops Drafting and Starts Acting: The Agentic AI Governance Gap in Law Firms Read guide →](https://rankshieldlegal.com/blog/agentic-ai-governance-gap-law-firms/)[Legal AI The New Duty of Technology Competence: What Model Rule 1.1 Now Expects You to Verify About AI Read guide →](https://rankshieldlegal.com/blog/duty-technology-competence-ai-aba-1-1/)
